Skip to content

Define portable policy evaluation and authorization specifications #142

Description

@woksin

Scope

Define exact portable policy IR and evaluation over typed artifact, authorization subject, caller identity, roles, multi-valued claims, scope/tenant and occurrence time. Preserve logical and/or grouping and constrained implementations. Add caller Given fixtures and allowed/denied outcomes.

Acceptance criteria

  • Missing/null/invalid claim or subject paths deny deterministically.
  • Case and multi-value behavior are specified.
  • Unsupported custom policy blocks rendering/execution.
  • No backend weakens conjunction, claims or custom behavior.
  • Stage/reference/Arc+ASP.NET realization pass shared vectors across HTTP and in-process execution.
  • Module/feature inheritance work in authorize cannot be bound at module or feature level #75 composes with use-site policies.

Child of #128; depends on ESM and constrained implementations.

Metadata

Metadata

Assignees

Labels

enhancementNew feature or request

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions